r/paloaltonetworks

PANW offer and refreshers

Hi folks-

I've an offer at PANW for Principal Engineer in Santa Clara, HQ.

Need to know if my offer is good.

Current TC: 340

PANW offer:
TC: 342 (base - 220k, 15% bonus and rest rsu)

My biggest question is - How are refreshers? Keep hearing that there are no refreshers.

Current company has good refreshers. I'll lose money if no refreshers given.

Need inputs. Thx

reddit.com
u/ThatCellist1755 — 9 hours ago

Anyone building custom tooling around Palo Alto firewalls?

I finally got around to spinning up a VM-Series in GCP (way easier than I expected with the marketplace image), and I've been using it as a sandbox to learn automation and test ideas.

I'm curious what kind of tools or side projects people have built around PAN-OS.

Things like:

  • custom EDL automation
  • log enrichment
  • dynamic address groups
  • API wrappers
  • Ansible playbooks
  • GlobalProtect utilities
  • Panorama automation

Mostly looking for inspiration. Would love to see what people are building.

reddit.com
u/Jay_Ferreira — 2 days ago

User-ID best practice

Current setup: About half a dozen firewalls, including one for GlobalProtect, all managed by Panorama. User-ID data redistribution is configured in the devices template stack and the only source are some User-ID agent Windows servers.

It usually works, but there are issues if a user has to switch from LAN to VPN via mobile hotspot during the day.

Would it be better to have the agent servers send their data to the Panorama, have the GP firewall also send its User-ID data to the Panorama and the Panorama distributes it to all firewalls?

How's your User-ID data redistribution set up?

reddit.com
u/NazgulNr5 — 2 days ago

Prisma Access, Global Protect, User-ID, and on-prem NGFWs

Rejected title: "Prisma Access, User-ID, and Me"

Hey there folks, hoping someone here might be able to point me in the right direction. I've inherited an environment that's running a combination of things: about 20 on-prem NGFWs, including cloud-hosted VM-series, Prisma Access (specifically Mobile Users), Cloud Identity Engine, and Panorama managing all of these.

The issue I've been running into is a bit of a weird one: to get User-ID working "again". Apparently, when this environment was built (about ~3-4 years ago), the MSP tasked with it left with User-ID (and applicable security policies) working. Something in 2023 or 2024 broke it, and there was no-one available at the time to investigate, so the folks there just focused on working around it.

Currently, I know that CIE and Prisma Access/Global Protect are functional in fetching and applying User-ID information. For actual remote users, there's no problems. However, we also have internal host discovery enabled for employees so that, when they're on-site, it doesn't build a tunnel and force all that traffic over to the Prisma gateways; instead, the GP instance just flips to "Internal". All as expected so far.

Except, for some reason, when the Global Protect App switches to "Internal", no User-ID information is being passed on to the NGFW, despite authentication having been successful (and therefore, to my understanding, having "captured" user info).

My guess is that there's some redistribution component that was changed in the past and is now broken, except I have no what it is, and having gone around to look, I'm finding a lot of conflicting or overlapping advice/suggestions: configure local gateways and put them in the Mobile_Users_Template->Portal->Agent (etc.) config; configure it in Remote Networks (a subscription we don't use); there was some major feature changes that possibly broke it in 2024; and so on.

Basically, I'm just trying to understand: is there a configuration with the assets we currently have that would allow local users to authenticate, not have GP build a tunnel, but still pass the User-ID information to the NGFW?

reddit.com
u/snovah — 3 days ago

NGFW Clustering 12.1.4-h7

I'm currently working on setting up NGFW clustering for the new PA-5540s and am hitting an immediate roadblock in the clustering process. Right when I setup the cluster our secondary node shows failed because it's avoiding split-brain. The management interfaces can ping each other and the hsci links are online and 100G. As far as I can tell this should be working.

Does anyone have experience with this new tech?

reddit.com
u/Kirby127 — 3 days ago

Work-life balance on the Prisma team at Palo Alto Networks?

I’m joining Palo Alto Networks Prisma AIRS as a new grad software engineer soon. Does anyone here know what is the work-life balance generally like across engineering teams, including typical hours, workload, and on-call expectations?

reddit.com
u/eirlude420 — 2 days ago
▲ 27 r/paloaltonetworks+1 crossposts

The PAN-OS zero-day is a free masterclass in network segmentation

The Arctic Wolf report on the Palo Alto CVE (2026-0257) is fascinating. Attackers bypass GlobalProtect authentication entirely. They spin up a session with zero credentials and immediately drop Qilin ransomware across the domain. It is brutally efficient.

This highlights exactly why monolithic perimeter defense is a dead concept. When one proprietary gateway holds all the keys, a single bug compromises everything.

We can use this exploit as a structural template to improve. We have to build systems assuming the edge will fail. I isolate all external entry nodes on strict VLANs. If a gateway is breached, aggressive firewall rules block any lateral pivot to the internal databases. The blast radius stops right there. Open-source solutions combined with hard segmentation give you actual control over the traffic flow.

How are you guys isolating your VPN portals to prevent rapid lateral pivots?

reddit.com
u/EnthusiasmRoutine — 4 days ago

Blocking Port/URL Issue

What up, all you smart people? I could use some assistance.

I have been given an internal address that needs to be accessible to the public.

-app.company.com

I set up a NAT rule and made it accessible.

Now they want a specific port/url to be blocked from the public so people can't try to log into the management side of things.

-https://app.company.com:PORT/app/manager/

I thought I set up a correct security policy to block it, but I'm still able to hit the page after committing. So, I thought I would see if anyone could give me an idea on what to do before I pay someone to tell me what I'm doing wrong. Any assistance would be appreciated!

reddit.com
u/CrazyBinnegin — 5 days ago

PAN-OS 10.2.18-h9 released

PAN-OS 10.2.18-h9 was released (for hardware that still has support, e.g. PA-220).

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-release-notes/pan-os-10-2-18-known-and-addressed-issues/pan-os-10-2-18-h9-addressed-issues

PAN-329698 (OCTEON, MIPS, platforms only) Fixed an issue where the data plane became unresponsive. With this fix, the data plane operates stably.
PAN-308775 (Firewalls in active/passive configurations only) Fixed an issue where NTP status intermittently showed as rejected on the active firewall, which prevented the firewalls from synchronizing time.

We have not experienced unresponsive data planes with our PA-220 (OCTEON-based CPU).

We have not experienced problems with NTP on our PA-220 in A/P.

We have recently moved from 10.2.16-h7 to 10.2.16-h9, as 10.2.16-hX is still the preferred release for 10.2. I see no CVEs listed in 10.2.16-h9, so we'll still not be moving beyond 10.2.16-hX.

https://security.paloaltonetworks.com/?version=PAN-OS+10.2.16-h9&product=PAN-OS&sort=-date

docs.paloaltonetworks.com
u/Sure-Squirrel8384 — 4 days ago

Palo Alto training videos

My employer has given me access to Udemy for training videos but I'm having a hard time understanding the speakers due to their thick English accents.

Any recommendations?

reddit.com
u/SynchN3rd — 5 days ago
▲ 24 r/paloaltonetworks+3 crossposts

Technical analysis: CVE-2026-0257 exploitation leading to Qilin ransomware

Recent incident response findings detail how CVE-2026-0257 in PAN-OS GlobalProtect has been leveraged as an initial access vector, followed by credential theft, lateral movement, and eventual Qilin ransomware deployment. This analysis covers the exploitation chain, affected versions, observed TTPs, IoCs, mitigation guidance, and key takeaways for PAN-OS administrators.

thecybersecguru.com
u/NapierPalm — 5 days ago

Anyone running 11.1.13-h9?

11.1.13-h9 will be our first move to 11.1.13-hX.

We've been on 11.1.10-hX since 11.1.10-h1 went Preferred (I believe we started at 11.1.10-h3 as we always delay some months before moving minor versions) and have upgraded to various hotfixes about once a month or so, with our final install at 11.1.10-h26.

11.1.13 (w/o hotfix) went preferred Jan 15. We typically wait 6 months before moving. We we do move, we go to the latest hotfix for a preferred minor release, at least once it's been out for a few weeks. 11.1.13-h3 went preferred Apr 21; 11.1.13-h9 released July 6 so its had two full weeks. It addresses two more CVEs not fixed in previous 11.1.10-hXX or 11.1.13-hX releases.

Any problems spotted so far with 11.1.13-h9? We rolled it out to our various Test/Lab and firewalls with the least impact, and no problems so far.

reddit.com
u/Sure-Squirrel8384 — 6 days ago

Palo alto NGFW engineer certification

Hi!

Has anyone here taken the Palo Alto NGFW Engineer certification recently?

I’m thinking about taking it and was wondering how difficult you found it.

Does it include many CLI-related questions, or is it mostly focused on the GUI and troubleshooting?

For some background, I work with Panorama managing more than 10 Palo Alto firewalls.

My day-to-day work includes creating and modifying security and NAT rules, creating address objects and address groups, monitoring and analyzing traffic logs, and general firewall administration.

I don’t spend much time in the CLI, so I’m curious how much of the exam expects CLI knowledge.

I’d appreciate any advice on what to focus on or any areas that caught you by surprise.

Thanks!

reddit.com
u/SnooHamsters6951 — 6 days ago

¿Es recomendable usar terraform para configurar firewalls?

Hola,

Actualmente administro algunos fw pa (como 8 FW), y tengo una inquietud que quisiera saber como trabajan otros administradores la forma de configurar o administrar los equipos, ya que lei que es posible hacerlo con terraform y me llama la atencion pero no se si sea ideal o mas personas lo recomienden.

Realmente le veo muchas ventajas porque puedo tener un control de versiones, tener toda la config dentro de un repo y si quiero hacer la misma config pero para otro fw perfectamente puedo usar esos archivos de plantillas....

tengo curiosidad porque realmente me llama la atencion utilizar terraform para empezar a hacer este tipo de configuraciones, pero realmente no se si sea optimo o ideal, entiendo que configurar por codigo puede ser dificil al principio pero quisiera intentarlo ya que considero que es profecional y ordenado

Si tienen alguna sugerencia sobre como administran sus equipos o si simplemente consideran que panorama es lo mejor, los leo!

reddit.com
u/Jostin02 — 6 days ago

Pinging from cli doesn't work but from gui works fine

I know it's very silly question to ask but I tried pinging a destination from the cli of Palo alto FW (pan os 11.2.5) and it is throwing me invalid syntax error.
admin@PA-1> ping source 12.1.1.1 host 23.1.1.1

Invalid syntax.

AND

admin@PA-1> ping host 23.1.1.1 source 12.1.1.1

Invalid syntax.

AND

ping logical-router virtual_router1 source 12.1.1.1 host 12.1.1.2 (since I made a new virtual router)

Cannot open network namespace "ns2": No such file or directory

However the ping works perfectly from the gui (troubleshooting tab)

reddit.com
u/Pothandev — 7 days ago

Passive HA Pair - managing the passive member without an extra switch

Hey all,

Looked back a little bit in the forum and there's a couple of mentions of this scenario here and there, but just wanted to float the situation and possible solutions.

We've got an Passive HA pair of firewalls deployed at a manufacturing partner, and we establish management connectivity over an IPSec tunnel. ***EDIT: No panorama or SCM here, this is locally managed

Due to rackspace constraints, we could not spec a switch to facilitate access to the management ports (1u of space, we're using two small 500 series units). And we are currently not being allowed to patch the management interfaces for our firewalls out to the factory floor.

Am I missing something by thinking I can set up an L3 interface on my firewalls on an unused port (port 6 for example) and cross connect the firewalls (FW1 MGMT to FW2 port 6 + FW2 MGMT to FW1 port 6)? Then I can just set a static IP on each management interface and ensure that the routing and rules are enabled to facilitate connectivity over the tunnel?

It's not ideal, but am I missing anything major about this? I know that I won't be able to access both firewalls at the same time this way, as the data plane interfaces will be down on the passive member, but I already have connectivity to manage the primary firewall via the tunnel.

Anyone else overcome this solution (besides just getting a switch, or having them patch the mgmt interfaces out into their network)?

reddit.com
u/SuddenVegetable8801 — 9 days ago

SLS Disconnects

Was on vacation this past week and have received hundreds of alerts from SCM that my firewalls are disconnecting from SLS. Haven’t opened a ticket yet l, will wait until Monday, but when I attempted to login in to SCM it was just a never ending SSO loop. Not sure if this is myself only or something bigger going on, on the Palo side.

reddit.com
u/vinxavi7 — 8 days ago

Panorama SDWAN for Firewalls OOBM via internal and external DNS.

Hi guys, I am just wondering if this will work...We got Panorama SDWAN for years for several remote offices, all firewalls MGM are pointing to Panorama interface internal private IP via SDWAN tunnels..

Now I am thinking for some situations that I might need to have firewalls able to talk to Panorama via both SDWAn as well as external networks....

Thinking about getting panorama IP published via NAt with a public IP...and apply for dedicated public SSL certificate to Pano MGM interface, having both internal DNS mapping internal Pano IP and external DNS mapping Pano Public IP.. All firewall use Fqdn under Panorama MGM section instead its private IP. ...in this way, Firewall can talk to panorama via both internal and external network...is this common design for Enterprise Palo Infrastructure???

This will be useful, after upgraded our PanOS and SDWAN plugin, we might to push all to all devices at the same time, some devices in lower end hardware might be slow or shit itself to reboot without applying the new SDWAN config and dropped connections etc, later on it still can get he pushed config again from Panorama's Public IP...Anyone implement like this? Any issues?

Thanks John

reddit.com
u/Thegoogoodoll — 11 days ago

Palo Alto making SCM more desirable in our refresh, should we move to it now?

Palo Alto is putting better discounts on refreshes with SCM included and making non-SCM look less desirable over 5 years. Due to the attractive pricing over 5 years, should we ditch Panorama and move to SCM now because of this?

Estate <10 FWs

reddit.com
u/notSPRAYZ — 13 days ago

2-post rack for PA-520?

Looks like there is only one official rack and it's a 4-post rack mount kit. Can use it as a two post rack mount with two firewalls or is there an aftermarket kit anyone is using?

reddit.com
u/gnartato — 10 days ago